URLhaus Database

You are currently viewing the URLhaus database entry for https://goctoeic.edu.vn/szunpij/protected_9yYDVc_pl5cwz8aVjkz8Z/individual_profile/cliu5u4le_2269/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:418702
URL: https://goctoeic.edu.vn/szunpij/protected_9yYDVc_pl5cwz8aVjkz8Z/individual_profile/cliu5u4le_2269/
URL Status:Offline
Host: goctoeic.edu.vn
Date added:2020-07-24 05:03:13 UTC
Last online:2020-08-05 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-24 05:04:03 UTC to abuse{at}gmo[dot]jp)
Takedown time:12 days, 11 hours, 16 minutes Bad (down since 2020-08-05 16:20:16 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-24dat_B3459.docdoc 8c31e01d64ab35fee10650f47066018520ad0cbbe47d1c6d6907debbc8988da2Virustotal results 47.54%Heodo
2020-07-24dat_BYG00438.docdoc 6b19d60b725c1852e9ae04f54eda81e330faec55d14abaa6cbfc384119ff2c98Virustotal results 49.18% Heodo
2020-07-24INF.docdoc 680810ced71322512a57ff7105b70c304eb31070c55e3d510591e79510eae3f8Virustotal results 48.33% 
2020-07-24arc-2020_07_24-2227.docdoc cba9c3956e13feb14892d0edfbb6c304f5a050ec62a899ebefb3113a43dda43eVirustotal results 49.18% Heodo
2020-07-24doc-20200724-UA94860.docdoc 5572c7e494ab9ac6e07ab78d1eaa09658c5d52b613590fbd45dab38ac3e66455Virustotal results 47.54% 
2020-07-24File 20200724 501.docdoc 787310593eedfe67ce8f219412d01235728e11d10a53578b3e673db921be2833Virustotal results 47.54%Heodo
2020-07-24arc-VWV1505.docdoc 82237411edab3b0cd9bc01935c55ffb42b8ea2b2af9c7540f56375628d424420Virustotal results 47.54% 
2020-07-24file_2020_07_24_CN755.docdoc aadb1ef348657580765dd31c88bcd1e021dd9656710bf1615dd29d68e1d36e83Virustotal results 47.46% Heodo
2020-07-24doc_2020_07_24_NS023445.docdoc 3067d395de7661161d83b094f8bc41fd3dbc1cf4005fec8e9104100c0128fb7cVirustotal results 47.46% Heodo
2020-07-24FILE-2020_07_24.docdoc f786bab6efaedc6a4f36411d1732917929e89097b85917845016f7eb0ca6e2e8Virustotal results 49.15% 
2020-07-24ARC_2020_07_24_JY47727.docdoc 410a9f48f1f612819c5e10e8cbfaf3e38cb1021b5c93516ace19d9faf788652en/a Heodo
2020-07-24REP-2020_07_24-KYA539527.docdoc cdca918e9b3ebbf49b86e29fb68d77d4a1713ee7ed7f0f3901a3f3a171478eadVirustotal results 47.54% 
2020-07-24Rep-20200724.docdoc 6c367b2213de689d037cd7b663ad35ca64515345f4cd1f745d26741ad410fedbVirustotal results 47.54% 
2020-07-24REP-20200724.docdoc 052d7edc0e3713623074a7e629d4005eae2901c9ed7dce61fec770ec23d4db8cVirustotal results 47.54% 
2020-07-24inf 20200724.docdoc d368979a419eaac0edcc0dbdf6c70319dd94359ac32022efa48b9c82baa7d1e7Virustotal results 50.00% Heodo